Available for projects & agency overflow · Quick reply, from the person who does the work

I’ve received an email asking me to install a security patch

The message looks like an official alert, it names a vulnerability and offers a file to install: this is exactly the scenario of a documented campaign against WooCommerce merchants, and the “patch” is the hack itself.

Describe my issue Send a message

What the message claims, and why it is false

The scenario is documented. On 23 April 2025, Patchstack published its analysis of an email campaign imitating an official WooCommerce security alert. The message announces a flaw called “Unauthenticated Administrative Access”, states that your shop is affected, and invites you to download a patch and install it yourself. That flaw does not exist: it was invented for the campaign. The file on offer is the hack.

The staging is restrained, which is exactly what makes it work: administrative tone, a credible-sounding flaw name, measured urgency rather than panic, a single download button. This is nothing like crude banking phishing, and experienced merchants do click. Patchstack links the campaign to the same actor behind a December 2023 operation, which already used a fabricated vulnerability identifier.

What to check in thirty seconds

  • The message names a flaw and asks you to download a file and install it yourself.
  • The flaw name matches no advisory published in the vendor’s official channel.
  • The link looks like the official domain, but one letter has been swapped for an accented character.
  • The patch is presented as urgent while no update is offered in your own dashboard.
  • The file is a plugin archive to upload by hand, not an update offered by the back office.

Why the fake site’s address looks right

The link does not point at an obviously foreign domain. It points at one built through an IDN homograph attack: a letter of the legitimate name is replaced by a visually near-identical accented character. In an address bar, at browser font size, the difference is invisible. I am not reproducing the domain here.

The practical consequence matters more than the technique: “I looked at the address and it seemed fine” is not a defence against this campaign. The only reliable check is to not follow the link at all, and to open your own dashboard, or the vendor’s site, from a bookmark you saved yourself.

I clicked the link but installed nothing

Opening the page does not compromise the shop. The mechanism Patchstack describes relies on you installing a plugin: until the file has been uploaded and activated in WordPress, the site has not been touched this way.

Two caveats, both worth acting on. If you typed administrator credentials into the page that opened, change them now and review recent back-office logins. If the file was downloaded to your computer, delete it without opening or unzipping it. Then run the checks below anyway: they take a few minutes and they settle the question, which beats living with an open one.

The published indicators, in the order I check them

  1. A plugin folder with a telling name

    Look in wp-content/plugins/ for a folder named authbypass-update. That is the indicator Patchstack published for this campaign. Finding it settles the matter: treat the site as compromised and move straight to incident handling.

  2. A folder inside uploads

    In wp-content/uploads/, look for a folder whose name starts with wp-cached-. Nothing of that shape belongs among media library files.

  3. An administrator account with a random name

    The plugin creates an administrator account with a random eight-character name, then hides it from the user list. The dashboard list is therefore unreliable: compare it against the actual contents of the users table in the database.

  4. A scheduled task running every minute

    The campaign schedules a randomly named WP-Cron task that runs every minute. Minute-level scheduling is abnormal on an ordinary shop, and it is one of the few things still visible through a WP-Cron inspection tool.

  5. A plugin list you cannot trust

    The malicious plugin removes itself from the plugin list. Compare what the back office shows against the real contents of wp-content/plugins/ over SFTP or through your host’s file manager.

  6. What was dropped afterwards

    The payload downloads webshells from known families (P.A.S.-Fork, p0wny, WSO) and sends credentials and site information to remote servers. If any earlier indicator is present, assume every credential has leaked and rotate them all: WordPress administrators, FTP/SFTP, database, hosting account.

The legitimate channel, and its limits

For a free plugin, an update arrives in the WordPress updates screen. For a paid one, it arrives through your account with the vendor, or automatically via the licence key registered on the site. There is no third route: no attachment, no archive sent by email, no direct download link in an unsolicited message.

That channel is not infallible either, and I would rather say so than sell a tidier rule. In June 2026, ShapedPlugin’s build and distribution infrastructure was compromised: several Pro versions were shipped with malicious code through the vendor’s own legitimate channel, with remediation starting on 16 June 2026 and publication on 22 June 2026. Only Pro versions were affected; the free versions on the WordPress.org repository were not. The lesson is not to distrust the official channel, but that watching your site’s files stays worthwhile even when you have done nothing unusual.

If any indicator is present

Describe your need in one minute

A few targeted questions so I can reply with an estimate rather than another questionnaire.

symptomes
depuis-quand
sauvegarde
acces-admin (facultatif)
Please provide an email or a phone number so I can get back to you.

Please provide an email or a phone number so I can get back to you.

Frequently asked questions

The email names a specific vulnerability. Doesn’t that make it legitimate?
No. The April 2025 campaign announced a flaw invented from scratch, and the same actor had already used a fabricated identifier in December 2023. A flaw name is verified in the vendor’s official channel, never in the message quoting it.
I installed the file and then uninstalled it. Is that enough?
No. The plugin drops other files, creates a hidden administrator account and a scheduled task that all outlive it. Uninstalling removes only the visible part.
How do I verify a message that appears to come from my vendor or host?
I never use the link in the message. I open the site dashboard and the vendor’s site from my own bookmarks and check whether the information is there. If it isn’t, the message is worthless.
My site works normally. Does that rule out the risk?
No. The campaign is built to stay quiet: the plugin hides from the plugin list, the administrator account it creates is hidden too, and visitors see no change. No symptom is not proof.
Should I change every password if an indicator is present?
Yes. The payload described sends credentials and site information to remote servers. I rotate WordPress administrator accounts, FTP/SFTP access, database credentials and the hosting account, then delete any account I cannot account for.